> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Policy

> Create a new policy configuration



## OpenAPI

````yaml /openapi/9.0/aviatrix-api.json put /v2.5/api/microseg/policy-list
openapi: 3.1.0
info:
  title: Aviatrix Controller API
  version: '9.0'
  description: >-
    Aviatrix Controller API — version 9.0. Selected operations with Mintlify
    metadata.
servers: []
security: []
tags:
  - name: policies
    x-group: Policies
  - name: authentication
    x-group: Authentication
  - name: account-management
    x-group: Account Management
  - name: rbac
    x-group: RBAC & Permissions
  - name: gateways
    x-group: Gateways
  - name: transit
    x-group: Transit
  - name: nat
    x-group: NAT
  - name: app-domains
    x-group: SmartGroups
  - name: certificates
    x-group: Certificates
  - name: mitm
    x-group: MITM
  - name: monitoring
    x-group: Monitoring & Diagnostics
  - name: fqdn
    x-group: FQDN
  - name: logging
    x-group: Logging
  - name: vpn
    x-group: UserVPN
  - name: site-to-cloud
    x-group: Site-to-Cloud
  - name: controller
    x-group: Controller
  - name: bgp
    x-group: BGP
  - name: general
    x-group: General
  - name: firenet
    x-group: FireNet
  - name: networking
    x-group: Networking
  - name: tgw
    x-group: AWS TGW
  - name: ips
    x-group: IPS
  - name: saml
    x-group: SAML
paths:
  /v2.5/api/microseg/policy-list:
    put:
      tags:
        - policies
      operationId: policyCreate
      parameters:
        - name: Authorization
          in: header
          required: true
          description: 'Controller ID in the format: cid <CID>.'
          schema:
            type: string
            example: cid <CID>
            default: cid <CID>
          example: cid <CID>
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/pocMicrosegPolicyInputList'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/pocMicrosegPolicyList'
          description: POST operation response
        default:
          $ref: '#/components/responses/general_response_v25'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: >-
            curl -sk -X PUT "https://<controller>/v2.5/api/microseg/policy-list"
            \
              -H "Authorization: cid <CID>"
        - lang: python
          label: Python
          source: |-
            import requests

            url = "https://<controller>/v2.5/api/microseg/policy-list"
            headers = {"Authorization": "cid <CID>"}

            response = requests.put(url, headers=headers)
            print(response.text)
        - lang: go
          label: Go
          source: |-
            package main

            import (
              "fmt"
              "net/http"
            )

            func main() {
              req, _ := http.NewRequest("PUT", "https://<controller>/v2.5/api/microseg/policy-list", nil)
              req.Header.Set("Authorization", "cid <CID>")

              client := &http.Client{}
              resp, err := client.Do(req)
              if err != nil {
                panic(err)
              }
              defer resp.Body.Close()

              fmt.Println(resp.Status)
            }
components:
  schemas:
    pocMicrosegPolicyInputList:
      description: The Micro-Segmentation Policy object list request format.
      properties:
        policies:
          description: List of Micro-Segmentation Policy input objects.
          items:
            $ref: '#/components/schemas/pocMicrosegPolicyInput'
          type: array
      required:
        - policies
      type: object
    pocMicrosegPolicyList:
      description: The Micro-Segmentation Policy object list response format.
      example:
        policies:
          - action: ACTION_UNSPECIFIED
            decrypt_policy: DECRYPT_UNSPECIFIED
            desc: desc
            dst_ads:
              - dst_ads
              - dst_ads
            exclude_sg_orchestration: true
            flow_app_requirement: APP_UNSPECIFIED
            logging: true
            name: name
            port_ranges:
              - hi: 0
                lo: 6
              - hi: 0
                lo: 6
            priority: 1
            protocol: PROTOCOL_UNSPECIFIED
            src_ads:
              - src_ads
              - src_ads
            system_resource: true
            uuid: uuid
            watch: true
            web_filters:
              - web_filters
              - web_filters
          - action: ACTION_UNSPECIFIED
            decrypt_policy: DECRYPT_UNSPECIFIED
            desc: desc
            dst_ads:
              - dst_ads
              - dst_ads
            exclude_sg_orchestration: true
            flow_app_requirement: APP_UNSPECIFIED
            logging: true
            name: name
            port_ranges:
              - hi: 0
                lo: 6
              - hi: 0
                lo: 6
            priority: 1
            protocol: PROTOCOL_UNSPECIFIED
            src_ads:
              - src_ads
              - src_ads
            system_resource: true
            uuid: uuid
            watch: true
            web_filters:
              - web_filters
              - web_filters
      properties:
        policies:
          description: List of Micro-Segmentation Policy objects.
          items:
            $ref: '#/components/schemas/pocMicrosegPolicy'
          type: array
      required:
        - policies
      title: ListMicrosegPolicyResponse
      type: object
    pocMicrosegPolicyInput:
      properties:
        action:
          $ref: '#/components/schemas/MicrosegPolicyAction'
        ai_inspection_mode:
          $ref: '#/components/schemas/AIInspectionMode'
        decrypt_policy:
          $ref: '#/components/schemas/AllowDecrypt'
        desc:
          title: Policy desc
          type: string
        dst_ads:
          items:
            type: string
          title: Destination AppDomains
          type: array
        egress_path:
          $ref: '#/components/schemas/EgressPath'
        enforcement:
          $ref: '#/components/schemas/EnforcementMode'
        exclude_sg_orchestration:
          type: boolean
        flow_app_requirement:
          $ref: '#/components/schemas/FlowAppRequirement'
        log_profile:
          description: >
            There are 3 system defined profiles:

            def000ad-7000-0000-0000-000000000001=log on start (default when
            empty)

            def000ad-7000-0000-0000-000000000002=log on end

            def000ad-7000-0000-0000-000000000003=log on start and end

            Log on start will log an entry at the start of the transaction, this
            will include

            the enforcement decision.

            Log on end will log an entry after the transaction and includes the
            number of

            received/transmitted bytes for the transaction (only L7 for now)

            Please refer to the documentation for more details.
          title: UUID of the LOG profile
        logging:
          type: boolean
        metadata:
          $ref: '#/components/schemas/dcfMetadata'
        name:
          title: Policy name
          type: string
        port_ranges:
          items:
            $ref: '#/components/schemas/pocPortRange'
          type: array
        priority:
          description: Priority of policy. Lower value means higher priority.
          format: int32
          type: integer
        protocol:
          $ref: '#/components/schemas/MicrosegPolicyProtocol'
        src_ads:
          items:
            type: string
          title: Source AppDomains
          type: array
        tls_profile:
          title: UUID of the TLS profile
          type: string
        uuid:
          title: Policy UUID
          type: string
        watch:
          deprecated: true
          description: >-
            Deprecated: use 'enforcement' instead. true maps to
            enforcement=MONITOR, false maps to enforcement=ENFORCE.
          type: boolean
        web_filters:
          items:
            type: string
          title: WebFilter List
          type: array
      required:
        - action
        - dst_ads
        - name
        - priority
        - protocol
        - src_ads
      title: Policy Config
      type: object
    pocMicrosegPolicy:
      example:
        action: ACTION_UNSPECIFIED
        decrypt_policy: DECRYPT_UNSPECIFIED
        desc: desc
        dst_ads:
          - dst_ads
          - dst_ads
        exclude_sg_orchestration: true
        flow_app_requirement: APP_UNSPECIFIED
        log_profile: uuid
        logging: true
        name: name
        port_ranges:
          - hi: 0
            lo: 6
          - hi: 0
            lo: 6
        priority: 1
        protocol: PROTOCOL_UNSPECIFIED
        src_ads:
          - src_ads
          - src_ads
        system_resource: true
        tls_profile: uuid
        uuid: uuid
        watch: true
        web_filters:
          - web_filters
          - web_filters
      properties:
        action:
          $ref: '#/components/schemas/MicrosegPolicyAction'
        ai_inspection_mode:
          $ref: '#/components/schemas/AIInspectionMode'
        decrypt_policy:
          $ref: '#/components/schemas/AllowDecrypt'
        desc:
          title: Policy desc
          type: string
        dst_ads:
          items:
            type: string
          title: Destination AppDomains
          type: array
        egress_path:
          $ref: '#/components/schemas/EgressPath'
        enforcement:
          $ref: '#/components/schemas/EnforcementMode'
        exclude_sg_orchestration:
          type: boolean
        flow_app_requirement:
          $ref: '#/components/schemas/FlowAppRequirement'
        log_profile:
          description: >
            There are 3 system defined profiles:

            def000ad-7000-0000-0000-000000000001=log on start (default when
            empty)

            def000ad-7000-0000-0000-000000000002=log on end

            def000ad-7000-0000-0000-000000000003=log on start and end

            Log on start will log an entry at the start of the transaction, this
            will include

            the enforcement decision.

            Log on end will log an entry after the transaction and includes the
            number of

            received/transmitted bytes for the transaction (only L7 for now)

            Please refer to the documentation for more details.
          title: UUID of the LOG profile
          type: string
        logging:
          type: boolean
        metadata:
          $ref: '#/components/schemas/dcfMetadata'
        name:
          title: Policy name
          type: string
        port_ranges:
          items:
            $ref: '#/components/schemas/pocPortRange'
          type: array
        priority:
          description: Priority of policy. Lower value means higher priority.
          format: int32
          type: integer
        protocol:
          $ref: '#/components/schemas/MicrosegPolicyProtocol'
        src_ads:
          items:
            type: string
          title: Source AppDomains
          type: array
        system_resource:
          readOnly: true
          title: System created policy. Cannot be deleted or modified.
          type: boolean
        tls_profile:
          title: UUID of the TLS profile
          type: string
        uuid:
          title: Policy UUID
          type: string
        watch:
          deprecated: true
          description: >-
            Deprecated: use 'enforcement' instead. true maps to
            enforcement=MONITOR, false maps to enforcement=ENFORCE.
          type: boolean
        web_filters:
          items:
            type: string
          title: WebFilter List
          type: array
      required:
        - action
        - dst_ads
        - exclude_sg_orchestration
        - logging
        - name
        - port_ranges
        - priority
        - protocol
        - src_ads
        - uuid
        - watch
      title: Policy Config
      type: object
    general_response_v25:
      description: A generic API response container for v2.5 style APIs.
      properties:
        message:
          description: A human-readable message.
          type: string
      title: General Response v2.5
      type: object
    MicrosegPolicyAction:
      default: ACTION_UNSPECIFIED
      enum:
        - ACTION_UNSPECIFIED
        - PERMIT
        - DENY
        - INTRUSION_DETECTION_PERMIT
      type: string
    AIInspectionMode:
      default: AI_INSPECTION_DISABLED
      description: AI traffic inspection mode for per-policy control
      enum:
        - AI_INSPECTION_DISABLED
        - AI_INSPECTION_ENABLED
      type: string
    AllowDecrypt:
      default: DECRYPT_UNSPECIFIED
      enum:
        - DECRYPT_UNSPECIFIED
        - DECRYPT_ALLOWED
        - DECRYPT_NOT_ALLOWED
      type: string
    EgressPath:
      default: EGRESS_PATH_DEFAULT
      description: >-
        Egress path for this policy: EGRESS_PATH_DEFAULT marks traffic to be
        sent through the spoke's configured egress transit gateway (FireNet or
        TGW). EGRESS_PATH_LOCAL forces traffic out through the spoke VPC
        directly.
      enum:
        - EGRESS_PATH_DEFAULT
        - EGRESS_PATH_LOCAL
      type: string
    EnforcementMode:
      default: ENFORCE
      description: >
        Controls how this rule is applied. 'ENFORCE' applies the rule action to
        matching traffic. 'MONITOR' logs matches and increments counters but
        does not apply the action. 'DISABLE' stores the rule as a draft on the
        controller; it is not pushed to gateways.
      enum:
        - ENFORCE
        - MONITOR
        - DISABLE
      type: string
    FlowAppRequirement:
      default: APP_UNSPECIFIED
      enum:
        - APP_UNSPECIFIED
        - TLS_REQUIRED
        - NOT_TLS_REQUIRED
      type: string
    dcfMetadata:
      additionalProperties: true
      description: Metadata for DCF objects (Policy List, Policy Block, Policy)
      example:
        key1:
          k8s:
            resource-type: k8s-policylist
        key10: value10
        key2:
          k8s:
            resource-type: k8s-policylist
        key20: value20
        key3:
          k8s:
            resource-type: k8s-policylist
      type: object
    pocPortRange:
      example:
        hi: 0
        lo: 6
      properties:
        hi:
          format: int32
          type: integer
        lo:
          format: int32
          type: integer
      required:
        - hi
        - lo
      type: object
    MicrosegPolicyProtocol:
      default: PROTOCOL_UNSPECIFIED
      enum:
        - PROTOCOL_UNSPECIFIED
        - TCP
        - UDP
        - ICMP
      type: string
  responses:
    general_response_v25:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/general_response_v25'
      description: General v2.5 API response schema.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.